# Updating `.env` in Kubernetes Buzz Sheet uses the `buzz-sheet-env` Secret in the `buzz-sheet` namespace. The local `.env` file is ignored by Git and must never be committed. This repository uses hand-authored Kustomize manifests rather than a Kuber-managed Compose file, so synchronize `.env` with `kubectl`. ## Push an updated `.env` From the repository root, confirm that `kubectl` is connected to the intended cluster: ```bash cd /home/gunshiz/buzz-sheet kubectl config current-context kubectl get namespace buzz-sheet ``` Create or update the Secret without printing its values: ```bash kubectl create secret generic buzz-sheet-env \ --namespace buzz-sheet \ --from-env-file=.env \ --dry-run=client \ --output=yaml | kubectl apply --filename=- ``` Running pods do not reload Secret values automatically. Restart both the web application and the outbox worker, then wait for each rollout: ```bash kubectl rollout restart deployment/buzz-sheet \ --namespace buzz-sheet kubectl rollout restart deployment/buzz-sheet-worker \ --namespace buzz-sheet kubectl rollout status deployment/buzz-sheet \ --namespace buzz-sheet \ --timeout=10m kubectl rollout status deployment/buzz-sheet-worker \ --namespace buzz-sheet \ --timeout=10m ``` Verify PostgreSQL and Redis readiness, then inspect the application logs: ```bash curl -fsS 'https://guide.sudloh.com/api/health?ready=1' bun logs ``` The health response should report `"status":"ready"`, with both `database` and `redis` set to `"ok"`. ## Important exceptions - Updating the Secret does not apply database migrations or seed data. If `DATABASE_URL` now points to a new database, migrate and seed that database before restarting the application. - Better Auth errors about missing database fields require a schema migration. Pushing `.env` again will not fix them. - `NEXT_DEPLOYMENT_ID` is controlled by `buzz-sheet-config` and the immutable image revision. Do not change it for an environment-only update. - `NEXT_SERVER_ACTIONS_ENCRYPTION_KEY` is embedded during `next build`. Rotating it requires building and deploying a new image; restarting the existing image is not sufficient. - If `BETTER_AUTH_URL` or the public hostname changes, update the Kubernetes ingress and Cloudflare/DNS configuration as well. - `S3_ENDPOINT` is the private Garage API used for writes. `S3_PUBLIC_URL` is the public read-only CDN base (production uses `https://buzz-cdn.astrxl.dev`). Browser uploads go through the authenticated application route; do not point `S3_ENDPOINT` at the CDN hostname.